As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0343 [1.00] [M/H] Kwetsbaarheden verholpen in GeoNetwork door OpenGeo
OpenGeo patched three vulnerabilities in GeoNetwork, an open-source catalog application, affecting versions 4.4.5 through 4.4.11 and earlier releases of 4.4.12 and 4.2.17. A reflected cross-site scripting (XSS) flaw in the unauthenticated search function allows JavaScript injection via the uiconfig parameter, while an insecure XSLT processor configuration enables remote code execution for users with upload privileges. An unprotected application programming interface (API) endpoint permits unauthenticated attackers to upload arbitrary files, potentially leading to unauthorized write access and server compromise.
Why it matters: Organizations running GeoNetwork must upgrade to 4.4.12, 4.2.17, or later to prevent XSS attacks, arbitrary code execution by privileged users, and unauthorized file uploads that could compromise server integrity.
- Source published
- First seen by Cybersecurity Tracker